This form does not yet contain any fields.
    Login
    « Claims-Based Authentication Patterns & Practices Guide updated for ADFSv2 RC | Main | ADFSv2 – SDK Updated for RC »
    Saturday
    Dec262009

    Syncing Passwords to the Cloud: Sign of the Apocalypse?

    So Pamela Dingle and Patrick Harding have been kicking around a discussion about the potential security liability of synchronizing enterprise passwords out to cloud applications. You should go read the whole thing, but the Cliff Notes version goes like this:

    Giving away the shared secret that (for better or worse) is often the key to your internal windows domain and to anything linked into that domain, is a really stupid idea.

    It’s an interesting premise, and rather flies in the face of the ILM/FIM integrator school of thought that says “I don’t care where your identities are, I’ll give you SSO by syncing everything everywhere.”

    Now, clearly this argument resonates strongly with a Fed Zealot like me (and Pamela, and Patrick), since one of the benefits of the claims model is the fact that AuthN, and passwords by extension, are handled locally by the user’s authentication source rather than being shipped out to a bunch of connected systems. And, if you’re not BP (or maybe even if you are), one of the issues with the move to the Cloud is that it’s very much a “black box” environment, where local IT has no actual control over how anything is administered, secured, or controlled. (Of course, the assumption here is that you’ve done due diligence on your Cloud vendor on these matters prior to porting your apps out to them.)

    Reader Comments

    There are no comments for this journal entry. To create a new comment, use the form below.

    PostPost a New Comment

    Enter your information below to add a new comment.

    My response is on my own website »
    Author Email (optional):
    Author URL (optional):
    Post:
     
    All HTML will be escaped. Hyperlinks will be created for URLs automatically.